The Net Unit implements the connection of the units to the networks of the SE server and to customer networks. In addition, private networks are available for internal communication in the SE server.
The following logical networks are supported:
Public management networks
Management Admin Network Public (MANPU)
Management Optional Admin Network Public (MONPU): the additive administration network can be configured when required (e.g. when AIS Connect is not to be operated via MANPU).
Management Network Private
Management Control Network Private (MCNPR) for SE server communication
Management Optional Network Private (MONPR): when required, up to 8 additive networks MONPR<n> (where <n>= 01..08) can be configured for SE server communication.
Management Control Network Local (MCNLO) for the local SE server communication
Management SVP Network Private (MSNPR) enables SVP communication to the SU /390 on SE700/SE500
Data Network Public
Data Network Public (DANPU): when required, up to 8 additive networks DANPU<n> (where <n>= 01..08) can be configured for connecting applications to the public customer network.
Data Network Private
Data Network Private (DANPR): when required, up to 99 networks DANPR<n> (where <n>= 01..99) can be configured for internal private customer networks for SE servers.
Figure 2: Block diagram of the Net Unit
The use of different networks means that components of one network cannot influence the other network, in other words the networks are protected from each other.
Furthermore, the ACL services (TCP/UDP ports) of the DANPU<xx>, MANPU, MONPU, DANPR<xx> and MONPR<xx> networks can be restricted in the Net Unit configuration (see section "Security at Net Unit level").
The base operating system of the HNC and SU x86 can only be reached over the internal networks and are thus protected from the customer networks.
Exception: This does not apply if Net-Storage with connection to MANPU or DANPU is configured on HNC or SU x86!
With a suitable firewall setting on HNC or SU x86, you can ensure that only the port required for communication (via NFS v3 or v4) with the Net-Storage is accessible.
In addition to the connections of the units to the switches of the Net Unit (for use by the guest systems), direct cabling from the units to the customer network can also be used.